Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Wealth management third-party risk graphic for youX leak article

A third-party breach is when an attacker compromises a vendor, supplier, or platform your business relies on — and your data gets caught in the blast radius. It’s not your systems that were broken into. It’s someone else’s. But it’s still your data, and under Australian privacy law, it’s still your problem.

This isn’t a theoretical risk. Last week, Ernst & Young disclosed a breach caused by the compromise of a third-party support ticketing platform. Between late March and mid-April 2026, an attacker accessed the platform and downloaded documents containing client tax and financial information. EY’s own systems weren’t breached — but the data was exposed all the same.

Why This Matters for Australian Businesses

Most businesses — especially in financial services and wealth management — use a stack of third-party platforms that touch client data: CRMs, document portals, help desk tools, cloud accounting systems, and client onboarding platforms. Each one is a potential exposure point.

Under the Privacy Act 1988, the organisation that collected the personal information remains accountable for how it’s handled — even if the breach happens in a vendor’s system. The OAIC doesn’t distinguish between “our breach” and “their breach” when it comes to your notification obligations.

We see this blind spot regularly in our wealth management and advisory clients. They’ve invested in securing their own environment, but haven’t audited the platforms their team uses daily to handle sensitive client documents.

What to Do About It

Audit which third-party platforms have access to client data. Check whether each one has a data processing agreement in place. Make sure your incident response plan covers a breach that originates outside your own network. And if you’re unsure where the gaps are, talk to us — our cybersecurity team can walk you through a third-party risk review without overcomplicating it.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →